In the past months we upgraded a large number of FortiWiFi 60D units to 5.2.4 and started seeing issues with units locking up and not responding randomly. The only way to resolve is to unplug power and reboot.
We are seeing this on a number of units. We send out logs to FortiAnalyzer and we found that after this hard reboot logging to memory is again enabled. We contacted Fortinet Support and this is a known big to be fixed in 5.2.7. I am not entirely convinced that this setting is causing the lock ups. Logs indicate nothing and in fact some units have few to no logs prior to lock up. Seems to be very random in nature, but also appears to only when during normal business hours.
Anyone else having any similar issues or thoughts on this?
-M
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
This is not the issue for us as we do not log to the flash disk and send everything to FortiAnalyzer. HOWEVER.... if a FWF60D unit is rebooted, after the reboot Log to Disk is "miraculously" enabled again. To combat this, we have a script that runs every day to make sure logging to disk is disabled. Even when logging to disk is disabled the units will lock up randomly.
It is not resolved in 5.2.6 and we were told it should be resolved in 5.2.7 which is slated to be released towards the end of April 2016. (We're not holding our breath)
Here is how to test your flash on a production unit:
http://kb.fortinet.com/kb/documentLink.do?externalID=FD37415
And how to test everything offline:
http://cookbook.fortinet....ip-test-documentation/
Matt - Who told you 5.2.7? Ticket# or reference? I would like to pass this along to my Fortinet guys.. Good thing I stuck around on 5.0.x train. What if you upgrade to 5.4.0?
Thanks,
Chris
Upgrade to 5.4.0.... You're funny. :)
I am not gutsy enough to try it on a production environment yet.
Hey before I call the TAC I ask myself...
Am I on the latest firmware? ;)
This gives Tier1/2 one less thing to hang up on me about.
We've done some testing and actually like 5.4 compare to 5.2. 5.0 is bullet proof at this point. 5.4 hasn't crashed yet.........wait for it.......
I have always tried to figure out "which" firmware is the best for production environments and always get a cold shoulder from those who should know. Don't break it if it ain't broke or stay bleeding edge to prevent vulnerabilities that happen. They both bite you in the ass eventually....
Chris
Matt I've confirmed your findings....
------ Forwarded Message -------- From: J <@fortinet.com> To: Chris Carson <c> Subject: RE: [Fwd: Fortinet Forums Miscellaneous -- FortiOS and FortiGate: [Matt Garrett] Re: FortiWiFi 60D units locking up] Date: Wed, 23 Mar 2016 20:09:02 +0000 I found the bug report and it pretty much describes what you guys are experiencing. The fix will be in the 5.2.7 release from what I’m seeing.
Hi Guys,
So I have implemented 5.2.7 on a FortiWifi 60D in hopes of resolving this problem but have found it still problematic. Although now it has not resulted in a complete device lock-up but rather the wireless that just becomes unresponsive whilst the wired network remains up. Has anyone else tested 5.2.7 and have some results?
Regards,
Craig
I haven't tried it yet. I have a unit in production that I might.
Any other thoughts on 5.2.7?
Thanks,
Chris
Did 5.4 solve this?
Fortigate <3
5.2.7 on 60Cs and 60Ds does not solve it. Only disabling the wifi NIC and adding a FAP does. We have attempted to work with TAC starting with 5.2.1, and every time the answer becomes "try the new firmware" Once they said 'try 5.4.0' that was enough. We insisted on a higher level TAC, with more access to the developers.
I can concur. Our 60c just locked up and we upgraded to 5.2.7 on Wednesday.
We might try disabling the wifi next.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.